Law / United States / Indiana
Disclosure of Security Breach Act, data base owner's duty to maintain reasonable security procedures and dispose of records
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
Commencement not set.
A security baseline statutes rule binding private bodies.
As of 14 September 2026.
What it requires
- This binds any 'data base owner' that owns or licenses computerized data including personal information of an Indiana resident. A data base owner already maintaining its own data security procedures as part of an information privacy, security policy, or compliance plan under the USA PATRIOT Act, Executive Order 13224, the Driver's Privacy Protection Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or HIPAA, and complying with that plan's own reasonable-procedures requirement, is exempt; a current or former health care provider that claimed the HIPAA-based exemption remains bound for personal information, including health records, if its own plan does not require, or is not implemented to provide, that protection once it stops being a HIPAA covered entity.
- Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard from unlawful use or disclosure any personal information of Indiana residents you collect or maintain.
- Do not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering the information illegible or unusable.
- There is no private right of action for a violation. A knowing or intentional failure to comply with either duty is a deceptive act, actionable only by the Indiana Attorney General, who may seek an injunction, a civil penalty of up to $5,000 per deceptive act, and reasonable investigation and litigation costs; a related series of acts or omissions constitutes one deceptive act.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Civil penalty under Sec. 3.5(f)(2), recoverable only by the Attorney General. The statute's own unit is a 'deceptive act' rather than a bare violation: a failure to comply with the safeguards duty (subsection (c)) or the disposal duty (subsection (d)) in connection with related acts or omissions constitutes one deceptive act under subsection (g). This is separate from, and much lower than, the $150,000-per-deceptive-act penalty at Ind. Code sec. 24-4.9-4-2 for a failure of the article's own breach-notification duty, which is this jurisdiction's privacy-topic row, not this one.
- Rule
- Per violation only
- As of
- 14 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 5,000
Who enforces it
Enforcement body
The Indiana Attorney General may bring an action under this section to obtain an injunction, a civil penalty of not more than $5,000 per deceptive act, and the Attorney General's reasonable costs of investigation and litigation. A knowing or intentional failure to comply with this section is actionable only by the Attorney General, never by a private plaintiff.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A data base owner, a person that owns or licenses computerized data including personal information of an Indiana resident, must implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect and safeguard that personal information from unlawful use or disclosure.
A data base owner must also not dispose of or abandon records or documents containing unencrypted and unredacted personal information of Indiana residents without shredding, incinerating, mutilating, erasing, or otherwise rendering it illegible or unusable. A data base owner that maintains its own data security procedures under a listed federal privacy or security regime, and complies with that regime's own reasonable-procedures requirement, is exempt.
A current or former health care provider that claimed the HIPAA-based exemption remains bound for personal information, including health records, if its own compliance plan does not require, or is not implemented to provide, that protection once the provider stops being a HIPAA covered entity.
A knowing or intentional failure to comply is a deceptive act, actionable only by the Indiana Attorney General, and a related series of acts or omissions in violation of this section constitutes one deceptive act.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, Indiana Code Article 4.9, Disclosure of Security Breach Act